Transaction Card NFC Challenge-Response Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing card-based transaction systems are vulnerable to replay attacks, where intercepted card and transaction information is used fraudulently, despite efforts to enhance security.
Innovation Solution
A challenge response security protocol using near field communication (NFC) between a user communication device and a transaction card, where session-specific challenge information is transmitted to the card, and the card responds with a digital signature, which is then authenticated.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional card-based transaction systems are used, then transaction convenience is improved, but security against replay attacks deteriorates
Solution Approach 1:
The patent implements dynamic challenge-response authentication where the card processor generates a unique challenge value for each transaction and verifies it against a stored response. This dynamic verification process ensures that each transaction is authenticated in real-time, preventing replay attacks while maintaining the convenience of card-based transactions.
Solution Approach 2:
The system employs feedback mechanisms where the card processor receives challenge values from the authentication server, processes them through the card, and returns verified responses. This feedback loop ensures continuous verification of transaction authenticity, strengthening security without complicating the user experience.
2Productivity
If card-based transactions are used, then transaction speed is improved, but transaction security deteriorates
Solution Approach 1:
The authentication server performs preliminary actions by pre-generating and storing challenge values associated with card identifiers before transactions occur. This preliminary preparation allows for rapid authentication during actual transactions, maintaining high transaction speed while ensuring security through pre-verified challenge-response pairs.
Solution Approach 2:
The patent replaces traditional mechanical card verification with electronic challenge-response authentication. The card processor electronically generates and verifies challenge values, substituting physical card handling with secure electronic verification that maintains speed while enhancing security against replay attacks.
3Reliability
If challenge response protocol is implemented, then security against replay attacks is improved, but device complexity increases
Solution Approach 1:
The card processor serves multiple functions: it processes transactions, generates challenge values, verifies authentication responses, and communicates with the authentication server. This multi-functionality consolidates security mechanisms within the existing card processing infrastructure, improving security without proportionally increasing device complexity.
Solution Approach 2:
The authentication server acts as an intermediary that manages the complexity of challenge value generation and verification. By centralizing authentication logic in the server, the patent simplifies the card processor's role to primarily handling transaction processing and basic challenge-response verification, thereby improving security while limiting complexity growth to the server rather than client devices.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly enhances transaction security by making it difficult for intercepting entities to use the information in replay attacks, thereby ensuring the authenticity of the transaction card and user presence.
Implementation Method 1
a near card field communication (NFC) interface
Data Source
AI summary
A method is provided for communicating with a transaction card having a card data processor, a near card field communication (NFC) interface, and a card memory having a unique card identifier stored therein. In this method, a user communication device establishes an NFC session with the transaction card and transmits to the transaction card an NFC data exchange format (NDEF) WRITE TAG command including session-specific challenge information. The user communication device transmits to the transaction card an NDEF READ TAG command and receives from the transaction card, card-specific challenge response information. The challenge response information is then used to authenticate the transaction card.


